The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting multiple vulnerabilities affecting internet-facing on-premises Microsoft SharePoint Server deployments, prompting an urgent call for organizations to secure exposed systems.
The agency said the flaws affect supported on-premises versions of SharePoint Server and are being used to bypass authentication, execute malicious code remotely, and establish persistence in compromised environments. Alongside the actively exploited vulnerabilities, Microsoft has also patched two additional SharePoint flaws that CISA believes could become attractive targets for attackers.
The warning comes as CISA continues to expand its Known Exploited Vulnerabilities (KEV) Catalog, having identified 11 Microsoft SharePoint vulnerabilities exploited in real-world attacks since late 2021. The latest alert underscores the ongoing security risks facing organizations that continue to operate internet-exposed on-premises collaboration platforms and sets the stage for more urgent remediation efforts.
Active Exploitation Prompts Immediate Patching
CISA said attackers are exploiting three vulnerabilities, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, against self-hosted SharePoint Server deployments, including SharePoint Server Subscription Edition.
According to the agency, successful exploitation allows attackers to bypass authentication, achieve remote code execution, steal Internet Information Services (IIS) machine keys, and establish persistence that can later be used to deploy malware or conduct additional post-compromise activity.
The warning follows Microsoft's latest Patch Tuesday updates, which also addressed two further SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-58644. Although those flaws are not currently known to have been exploited in the wild, Microsoft has identified them as likely targets for future attacks.
Internet security monitoring organization Shadowserver currently tracks nearly 10,000 internet-exposed Microsoft SharePoint servers, with more than 800 reportedly remaining unpatched against two of the actively exploited vulnerabilities. CISA has urged organizations to apply Microsoft's latest security updates, verify that patches have been installed successfully, reduce patch deployment timelines, and enable additional protections such as Windows Antimalware Scan Interface (AMSI) integration and Microsoft Defender Antivirus detections.
AI Is Raising the Pressure on Vulnerability Remediation
The latest warning arrives as CISA continues to shorten the window organizations have to respond to critical cyber threats. Earlier this month, the agency reduced the deadline for US federal agencies to remediate serious vulnerabilities to just three days under its updated Binding Operational Directive, reflecting what it describes as an increasingly aggressive threat landscape accelerated by AI.




